Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,497GitHub PoC 13,627VulnCheck XDB 8,198Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
75,445 exploits
VulnCheck XDB
local
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open ↗GitHub PoC
POC for CVE-2025-68613
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open ↗GitHub PoC★ 146
A tool designed to exploit CVE-2025-54068 and Remote Command Execution if the APP_KEY of the Livewire project is known.
Livewire vulnerable to remote command execution during property update hydration
100RISK
open ↗GitHub PoC
CVE-2021-3493 OverlayFS privilege escalation exploit framework with advanced red team features. Includes persistence mechanisms, post-exploitation modules, stealth capabilities, and comprehensive documentation. For authorized testing only.
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open ↗GitHub PoC
machevalia/CVE-2025-14733
WatchGuard Firebox iked Out of Bounds Write Vulnerability
83RISK
open ↗GitHub PoC
通过GitHub Copilot 辅助分析CVE-2025-68613漏洞
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open ↗GitHub PoC
ali-py3/Exploit-CVE-2025-68613
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open ↗GitHub PoC★ 1
js2py sandbox escape to reverse shell
An issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a
68RISK
open ↗GitHub PoC
This repository contains a laboratory-grade analysis and a **safe Proof-of-Concept** for the vulnerability **CVE-2025-68613**, affecting the workflow automation platform **n8n**.
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open ↗GitHub PoC
My poc to exploit this vuln :D
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open ↗GitHub PoC★ 2
CVE-2025-62215: Windows Kernel Race Condition + Double-Free EoP
Windows Kernel Elevation of Privilege Vulnerability
71RISK
open ↗GitHub PoC
PoC for HTTP/2 Rapid Reset DDoS Vulnerability - CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open ↗VulnCheck XDB
initial-access
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open ↗GitHub PoC
Ushbu videoda Metasploitable 2 tizimidagi distccd servisidagi zaiflikdan foydalanib, Kali Linux orqali remote shell olish ko‘rsatib beriladi.
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote at
60RISK
open ↗VulnCheck XDB
infoleak
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISK
open ↗GitHub PoC★ 98
CVE-2025-68613: n8n RCE vulnerability exploit and documentation
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open ↗GitHub PoC
Vuln lab for CVE-2024-3408 - D-Tale Authentication Bypass & RCE
Authentication Bypass and RCE in man-group/dtale
85RISK
open ↗GitHub PoC★ 1
Python toolkit for decrypting AES-256 and cracking PBKDF2 passwords from Grafana databases usually paired with (CVE-2021-43798)
Grafana path traversal
100RISK
open ↗GitHub PoC★ 28
Detection for CVE-2025-68613
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open ↗GitHub PoC
CVE-2025-68613
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open ↗GitHub PoC★ 6
A C++ security scanner tool to detect Cross-Site Scripting (XSS) vulnerabilities in Roundcube Webmail installations.
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the ani
76RISK
open ↗GitHub PoC★ 25
Public PoC + Scanner and research for CVE-2025-68613: Critical RCE in n8n Workflow Automation via Expression Injection (CVSS 10.0). Includes detection tools, full exploit, and remediation guidance.
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open ↗VulnCheck XDB
initial-access
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open ↗GitHub PoC
React2Shell Critical Vulnerability (CVE-2025-55182)
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗VulnCheck XDB
remote-with-credentials
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open ↗VulnCheck XDB
initial-access
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗VulnCheck XDB
initial-access
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.